Skip to content
COOEY

FAIL › dossier

SD-WAN and NetScaler

PRODUCT

· dossier confidence 20%

Citrix's SD-WAN and NetScaler products have a history of critical vulnerabilities, most recently an unauthenticated RCE (CVE-2026-8452) that CISA added to its KEV catalog. The company's track record shows a pattern of high-severity flaws being actively exploited before patches are widely deployed.

PROFILE
CategoryNetwork Security / SD-WANWhat they doCitrix provides SD-WAN and NetScaler ADC solutions for secure network traffic management and application delivery. Websitehttps://www.citrix.com ↗
SECURITY POSTURE

The company has a poor security track record, with multiple high-severity vulnerabilities in its SD-WAN and NetScaler products being actively exploited in the wild, including recent RCE and SQL injection flaws.

Notable failures
  • CVE-2019-12991 authenticated RCE
  • CVE-2019-12989 active SQL injection
  • CVE-2026-8452 unauthenticated RCE
Patterns: repeated unpatched high-severity RCEs; active exploitation of known vulnerabilities
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2019-12991 high Citrix SD-WAN and NetScaler suffered an authenticated command injection flaw that allowed attackers to execute arbitrary commands on the devices.
2022-03-25 CVE-2019-12989 high Citrix SD-WAN and NetScaler suffered a SQL injection vulnerability that was actively exploited in the wild.
Open questions: Citrix's current patch cadence for SD-WAN and NetScaler · Whether Citrix has implemented compensating controls for CVE-2026-8452
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-30 04:11:29.754453+00:00